Your computer is locked by Canada Police Association? A penalty fine of 100 Canadian dollars is required to unlock your computer? Never be tricked like this. Read this post to figure it out and remove such an infection once and for all.

Canadian Police Association PC lockup virus, technically called ransomware, is just one more fake program in the cyberspace. It can infect the computer system in no time and of course this tricky infection is resulted from the Internet. Once the computer get infected, it will attempt to lock the computer and display a false warning screen instead, trying to be convincing that the user has violated some laws and thus is required for a fine of certain amount to evade the due penalty, paid via prepaid Credit Card like Ukash, SafePayCard, etc. However, just bear in mind, never believe such kind of nonsense talk and such is just webscam to get rid of.

Canadian Police Association virus, as stated above, is classified as ransomware, aka PC lockup virus. It is one of the most wide-spread and yet the most destructive infections in the cyberspace. Also it is one of the most hard-to-remove viruses.

How Do I Get Infected with Canadian Police Associated virus?

Often, ransomware is spread via Trojans. So does Canadian Police Association virus. Such infection would invade the computer when you are clicking a suspicious link, or open an email with evil attachment, or even visiting some risky websites, etc. It can be almost everywhere it can be. So be careful when searching online.

What Does Canadian Police Association Virus Do to the Infected Computer?

Once the computer is compromised by Canadian Police Association virus, it will attempt to lock the computer from normal running and then display a scaring alert faking the local authorities’ name, and here as Canadian Police Association, to be convincing that the user has violated some local laws and then should be fined to unlock the computer. Usually the fine is required to pay via Ukash or Paysafecard. Remember that no legal authority does such a way to do their job. However, this is even not the whole story. If you get tricked this way, what you lost is not merely the paid money, but also the your credit card information, let alone that doing such way could actually contribute to nothing in terms of getting the computer back to normal. Hence, never never be scammed by such online trick and if you unfortunately stump upon this ransomware, please instantly follow below steps to unlock your computer.

Webcam control

Once infected, there would be a little more than usual that this ransomware virus would even attempt to trick the user into thinking they are under surveillance by webcam, as it always shows a fake screen in “recording” status. Actually this even makes no difference on the infected computer with no web cam at all. Apparently, the truth is ready to jump out at your call.

Deny Flash

Most ransomware exploits Java or Flash vulnerabilities to load the malicious code. In some cases denying or disabling flash on your system may suspend the Canadian Police Association virus and enable the user to navigate through the infected system. If this not a necessity for removal, skip to the removal options below these steps.

Note! This tutorial is effective for all GreenDot MoneyPak, Ukash and Paysafecard ransomware.

There are several removal options depending on the specific infection situations that you encounter. In many cases that the infected computer is still able to be booted into safe mode, you may use the removal option 1 via safe mode with command prompt troubleshooting method. In other cases that the computer is totally locked from safe mode operation, then you may have to try the removal option 2 using Anvi Rescue disk. Here we go. If any question, just let us know.

Removal Option 1 Safe Mode with Command Prompt Method

Step 1> Launch your PC into Safe Mode with Command Prompt. During the start, keep pressing F8 key till the Advanced Windows Options Menu shows up and then use the arrow key on the keyboard to highlight the Safe Mode with Command Prompt option and then press Enter. More details on How to Boot Windows into Safe Mode

Note: make sure you login your computer with administrative privileges. (login as admin)

Step 2> Once the Command Prompt appears you only have few seconds to type “explorer” and hit Enter. If you fail to do so within 2-3 seconds, the ransomware virus will not allow you to type anymore.

Removal Option 2 Using Anvi Rescue Disk to Remove the Ransomware and Repair the Infected Computer

Chances are your PC is heavily infected by this ransomware so that it is blocked from safe mode running as well. If such is the case, the removal may be a little bit complex and here we use Anvi Rescue Disk to demonstrate the removal steps and good luck to you. If any question in the process, just let us know.

Also below is a video of ransomware removal using Anvi Rescue Disk for your reference.

Please close BootUsb.exe tool after you successfully burn the file to USB drive when you get following message.

Now, you have bootable Anvi Rescue Disk to repair your computer.

Alternative Option

You can also record Anvi Rescue Disk iso image to a DV/DVD. Any CD/DVD record software is fine for burn iso image. If you don’t have any, you can download and install Nero Burning ROM and ImgBurn. Here we will use Nero Burning ROM for demonstration purpose.

Please open and start Nero Burning ROM and select Burn Image from the drop-down menu of the Recorder.

Click Burn button to start record the iso image. After a few minutes, you will have a bootable Anvi Rescue Disk to repair your computer.

Step 3>Restart your computer and configure your computer to boot from USB drive/DV/DVD that recorded Anvi Rescue Disk. Basically , you can use F8 to load USB boot menu.

For different motherboard, you may need to use the Delete or F2, F11 keys, to load the BIOS menu. Normally, the information how to enter the BIOS menu is displayed on the screen at the start of the OS boot.

The keys F1, F8, F10, F12 might be used for some motherboards, as well as the following key combinations:

Step> 6 Make sure that your computer is connected to network connection before you run a scan on your computer. Please scroll down the file and check the tutorial if you fail to connect your computer to Internet.

Step> 7 Please run a full scan by clicking the “Scan Computer” button in the middle of the program to detect and kill the PC lockup virus.

Step> 9 Switch to Repair tab. Scan and fix the registry error with the “Repair” module of Anvi Rescue Disk.

Important Notice: You must repair the registry error after kill the virus. You are probably disabled to boot your Windows without fixing registry damaged by the virus.

Step>10 Now your computer should be clean and rescued from the virus infection. Please restart your computer and boot into Normal Mode.

Step 11> Now your computer should be clean and rescued from the infection. Please restart your computer into the normal Windows mode.

Please note, some ransomware infection variant is seriously persistent, so you are highly recommended to download the antimalware Anvi Smart Defender in the rescue disk menu when the scan and repair is finished just as shown in below picture:

In the prompt window, click Yes button to download and install Anvi Smart Defender and perform a full scan to ensure all possible files of the infection is removed.